Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Proxy Traffic to Operation Triangulation Domains Indicative of C2 Beaconing
Alerts on proxy requests to specific suspect C2-related domains by host substring match.
sigmahigh2023-06-01Suspicious DNS Queries to Operation Triangulation-Like Domains for C2 Beaconing
Detects DNS queries to known Operation Triangulation-related domains that may indicate C2 beaconing.
sigmahigh2023-06-01Windows File Activity Indicators of Potential MOVEit Transfer CVE-2023-34362 Exploitation
Finds MOVEit Transfer webroot file and ASP.NET compilation artifacts on Windows that may indicate CVE-2023-34362 exploitation.
sigmahigh2023-06-01Webserver: Potential CVE-2023-25717 Ruckus Wireless Admin Injection via Unauthenticated HTTP GET
Alerts on suspicious GET requests to Ruckus Wireless Admin login endpoints containing '$(' payload markers.
sigmahigh2023-05-30Windows regsvr32 Execution from Suspicious DLL Paths
Alerts on regsvr32 runs whose command line references a DLL in highly suspicious Windows directories.
sigmaWindowshigh2023-05-26Windows regsvr32 Execution of calc with /s flag
Alerts on regsvr32.exe runs using /s with a command line ending in calc.
sigmahigh2023-05-26Windows rundll32.exe Execution via cmd/cscript/powershell with .dll and Suspicious Directories
Alerts on rundll32.exe execution with DLL arguments from common Windows script/LOLBins and suspicious staging paths.
sigmahigh2023-05-24Windows Registry: New ODBC Driver Registration in Suspicious Path
Alerts when Windows registers a new ODBC driver under the ODBCINST.INI area with details pointing to suspicious filesystem paths.
sigmaWindowshigh2023-05-23Windows: Odbcconf.EXE INSTALLDRIVER Use With Missing .dll Target
Flags odbcconf.exe running INSTALLDRIVER when the driver argument lacks a .dll extension.
sigmaWindowshigh2023-05-23Windows: BlueSky ransomware-related file and share access events
Alerts on Windows file/share access involving .bluesky and "DECRYPT FILES BLUESKY" artifact naming tied to BlueSky activity.
sigmahigh2023-05-23Windows Process Execution of Odbcconf.exe with -f Response File Flag
Alerts on Odbcconf.exe being run with -f to load a response file, excluding runonce-driven executions.
sigmaWindowshigh2023-05-22Windows: Suspicious Odbcconf.EXE REGSVR usage with non-DLL-suffixed target
Flags odbcconf.exe launched with REGSVR while the target lacks a .dll extension on Windows process creation.
sigmaWindowshigh2023-05-22Windows Process Execution: odbcconf.exe with DLL in Suspicious Path
Flags odbcconf.exe process launches when the command line references DLL-related paths in suspicious Windows locations.
sigmaWindowshigh2023-05-22Windows Registry Run Key Persistence Using Small Sieve Typo Value Strings
Flags registry Run-key writes on Windows with Small Sieve-specific typo and executable detail strings in value data.
sigmahigh2023-05-19Windows Process Creation: Detects Command-Line Ending With '.exe Platypus'
Alerts when a Windows process command line ends with '.exe Platypus', matching a Small Sieve indicator.
sigmahigh2023-05-19Windows: Small Sieve IoC File Creation via AppData and Typo Filename Indicators
Alerts on Windows file events with Small Sieve filename typo/path indicators or the OutlookDataPlus.txt IOCs.
sigmahigh2023-05-19Windows WerFault ReflectDebugger Registry Key Value Targeting
Flags registry set events targeting WerFault ReflectDebugger under Windows Error Reporting Hangs for potential persistence abuse.
sigmaWindowshigh2023-05-18Windows CreateStreamHash: Suspicious Embedded File Download Indicators via .zip TLD
Flags Windows downloads indicating .zip/ plus ':Zone' in target filenames for risky executable or script extensions.
sigmaWindowshigh2023-05-18Windows: Suspicious rundll32 Execution of advpack.dll with Ordinal RegisterOCX Calls
Identifies rundll32.exe launching advpack.dll with ordinal-style calls consistent with stealthy OCX registration behavior.
sigmaWindowshigh2023-05-17AWS CloudTrail: S3 Browser Creates IAM User or Access Key
Alerts on CloudTrail IAM CreateUser/CreateAccessKey actions initiated by a "S3 Browser" user agent.
sigmaCloudhigh2023-05-17